ETDA สำนักงานพัฒนาธุรกรรมทางอิเล็กทรอนิกส์
Electronic Transactions Development Agency
Home > List all groups > MoustachedBouncer

Threat Group Cards: A Threat Actor Encyclopedia

Permanent link APT group: MoustachedBouncer

NamesMoustachedBouncer (ESET)
CountryBelarus Belarus
MotivationInformation theft and espionage
First seen2014
Description(ESET) MoustachedBouncer is a cyberespionage group discovered by ESET Research and first publicly disclosed in this blogpost. The group has been active since at least 2014 and only targets foreign embassies in Belarus. Since 2020, MoustachedBouncer has most likely been able to perform adversary-in-the-middle (AitM) attacks at the ISP level, within Belarus, in order to compromise its targets. The group uses two separate toolsets that we have named NightClub and Disco.

While we track MoustachedBouncer as a separate group, we have found elements that make us assess with low confidence that they are closely collaborating with another group known as Winter Vivern.
ObservedSectors: Foreign embassies in Belarus.
Countries: Belarus.
Tools used

Last change to this card: 06 September 2023

Download this actor card in PDF or JSON format

Previous: Moonstone Sleet
Next: Muddled Libra

Digital Service Security Center
Electronic Transactions Development Agency

Follow us on

Facebook Twitter

Report incidents

Telephone +66 (0)2-123-1227
E-mail [email protected]